Flatpak 1.18.4 Released With Fixes for Six Security Vulnerabilities

Security fixes:

  • Prevent privileged overwrite of arbitrary files with an empty file or a
    symlink to /run/host/monitor/resolv.conf when a malicious app is installed
    (CVE-2026-97024, GHSA-8xgq-v545-vgvf; thanks to Sebastian Wick)
  • Prevent privileged deletion of arbitrary files when a malicious app
    is installed
    (CVE-2026-97023, GHSA-5p67-xh8x-rq54; thanks to Sebastian Wick)
  • When downloading apps or runtimes from an OCI repository that requires
    authentication, don’t make the authentication token visible to other users
    (CVE-2026-97025, GHSA-7rvf-rqr3-43j4; thanks to AISLE in cooperation
    with Red Hat)
  • Restrict permissions on temporary repository directories in
    /var/tmp/flatpak-cache-*
    (CVE-2026-97026, GHSA-r9w3-qx54-qvc8; thanks to AISLE in cooperation
    with Red Hat)
  • Filter .desktop and D-Bus .service files against an allowlist of fields,
    preventing denial of service and unintended interactions with host services
    (CVE-2026-97027, GHSA-v64f-hrwr-j4vh; thanks to Markus Göllnitz)
  • Prevent apps from sending signals to a process group that includes a
    parent process outside the app, causing denial of service by killing
    the desktop environment
    (CVE-2026-97029, GHSA-f3p8-vr7v-gxf2; thanks to Guthrie Armstrong,
    Coalition, Inc.)

Source: Release 1.18.4 · flatpak/flatpak · GitHub

6 Likes